About the JWT Decoder
JSON Web Tokens (JWT) are compact, URL-safe tokens widely used for authentication and authorization in web and mobile apps. A JWT has three Base64url-encoded parts separated by dots: a header describing the signing algorithm, a payload containing claims about the user, and a signature.
The JWT Decoder instantly decodes the header and payload into readable JSON and highlights standard claims such as issuer (iss), subject (sub), audience (aud), issued at (iat), not before (nbf) and expiration (exp), with timestamps converted to your local date and time. It tells you immediately whether the token has expired, which makes debugging login problems and API errors much faster. You can even paste a full "Bearer ..." header.
How to use the JWT Decoder
- Paste your JWT (with or without the "Bearer" prefix).
- Read the decoded header and payload JSON.
- Check the standard claims and expiry status.
- Copy the header or payload if needed.
Frequently asked questions
Does this tool verify the signature?
No. It decodes the token so you can inspect it. Signature verification requires the secret or public key and should be done on your server.
Is it safe to paste my token here?
Decoding happens entirely in your browser and nothing is sent anywhere. Still, treat production tokens like passwords and avoid sharing them.
Are JWTs encrypted?
Standard signed JWTs are only encoded, not encrypted. Anyone with the token can read its payload, so never store secrets in it.
